Skip to content
Notis

Connect incident alerts to an evidence search

When Better Stack sends an incident to Notis, search Rkvst for matching events and bring potential evidence into the response.

Trigger

Webhook received

Notis starts this workflow when an external tool or custom backend sends an HTTP request.

Action

Search Events

Tool to search events matching filter criteria with pagination. use when retrieving events by odata filter and paging through large result sets.

Why this helps

Switching between incident alerts and evidence records makes it easier to miss useful context.

  • Start an evidence search from the incident signal.
  • Reduce the back-and-forth between monitoring and evidence tools.
  • Give the responder a concise set of potential matches.

Setup

Build it in a few focused steps.

  • 1Connect Better Stack and Rkvst to Notis once through the portal.
  • 2Create an automation in the portal or ask Notis to build it conversationally.
  • 3Write one prompt asking Notis to use each incident's details as criteria for a Rkvst event search and summarize likely matches.
  • 4Select an incoming webhook trigger and choose a channel for run reports.
  • 5Send one real incident through the webhook and review whether the returned events are useful.

Questions about this workflow

How does Better Stack start the workflow?

Better Stack or a custom backend sends an HTTP request to the Notis webhook when it reports an incident.

Does this write evidence into Rkvst?

No. The selected action searches events and returns matches for review.

When this happens · Trigger

Do this · Action

Supported Triggers and Actions

Notis builds workflows that link Better stack to Rkvst. A trigger fires from one place; an action lands in another.

Better stack triggers

Rkvst actions

Recurring trigger

Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.

TriggerScheduled

Download Event Attachment

Tool to download an attachment from a specified event on an asset. use when you have asset uuid, event uuid, and attachment uuid, and want the raw binary content.

ActionInstant

Webhook trigger

Notis starts this workflow when an external tool or custom backend sends an HTTP request.

TriggerInstant

Get App Registration

Tool to retrieve details for a given app registration id. use after obtaining the application's uuid to inspect its configuration and credentials.

ActionInstant

Get Asset

Tool to retrieve details for a given asset. use after you have its uuid; set `at time` to get historical state.

ActionInstant

Get Blob

Tool to retrieve details of a blob by id. use after confirming the blob id.

ActionInstant

Get Event

Tool to retrieve details of a specified event. use when you need full metadata, attributes, and associated trails of an existing event in datatrails.

ActionInstant

Get IAM Subject

Tool to retrieve iam subject details. use when you need to fetch details for a specific iam subject by its id.

ActionInstant

Get Member

Tool to retrieve details for a given member id. use after obtaining a valid member uuid.

ActionInstant

Get Public Asset

Tool to retrieve details for a public asset. use when you have a public asset uuid.

ActionInstant

Connect any two apps with Notis in the middle.

Better stack and Rkvst, or any other combination from 1,000+ integrations.

When this happens · Trigger

Do this · Action

Save your first hour today.

7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Rkvst.